DPDP Rules for Indian Schools: The Exemption You Have, and the Six Things You Still Owe

Published 2026-08-19 · 11 min read · By the AcadLynk editorial team

Most coverage aimed at schools says you now need verifiable parental consent to process student data. That is wrong. The Fourth Schedule of the DPDP Rules exempts schools for academic activities and student safety. The relief lasts about one paragraph, because the exemption is purpose-bound and everything else still applies.

Quick answer: Indian schools do not need verifiable parental consent to process student data for academic activities or student safety. The Fourth Schedule of the Digital Personal Data Protection Rules 2025 switches off Sections 9(1) and 9(3) of the DPDP Act for schools, provided processing stays strictly within those purposes. The exemption is purpose-bound rather than institution-wide, so it does not cover sharing student data with vendors, coaching centres or marketing. Every other obligation still applies to schools in full: itemised notice, purpose-limited retention, reasonable security safeguards, breach notification within 72 hours, and honouring parent and student data rights. The Rules were notified on 13 November 2025 and the substantive obligations come into force on 12 May 2027.

The four dates that decide your timeline

The Digital Personal Data Protection Act was passed in August 2023 and then had no practical effect for over two years, because the operational detail was missing: what a notice must contain, how long data may be kept, what verifiable consent actually means, what happens after a breach. The Rules supplied that detail, and they are what turned the Act into a compliance obligation with a shape and a deadline.

DateWhat happened, or happens
August 2023DPDP Act enacted. Principles set, operational detail absent.
13 November 2025DPDP Rules 2025 notified by MeitY. The framework becomes concrete.
12 May 2027Rules 3 and 5 to 16, plus 22 and 23, come into force - 18 months after publication. This is the date schools should plan against.
TodayRoughly nine months of runway. Enough to do this calmly, not enough to start late.

The default rule for children, and why it alarmed schools

Under the Act a child is anyone under 18. Section 9(1) requires a data fiduciary to obtain verifiable parental consent before processing a child’s personal data. Section 9(3) restricts tracking, behavioural monitoring and targeted advertising directed at children. Read those two provisions alone and a school looks completely stuck, because a school tracks attendance, monitors behaviour and writes it on a report card, and records health, transport, exam and disciplinary data as a matter of routine. That reading produces an absurd conclusion - that a school would need fresh verifiable consent to mark a register - and it is the reading behind most of the anxious content aimed at school leaders in the last year.

The Fourth Schedule: the exemption schools were not told about

The Rules anticipated the problem. The Fourth Schedule lists classes of data fiduciary for whom Sections 9(1) and 9(3) do not apply, provided the processing stays strictly within a stated purpose. Schools and educational institutions are on that list, permitted to process children’s personal data for academic activities - stated to include tracking and behavioural monitoring - and for the safety of enrolled students. So attendance, marks, conduct remarks and student safety measures do not require a verifiable parental consent workflow. Anyone who told you otherwise was reading the Act without the Rules.

  • Schools and educational institutions: academic activities, including tracking and behavioural monitoring, plus the safety of enrolled students
  • Crèches and daycare centres: an equivalent allowance scoped to child safety
  • Transport providers engaged by the institution: location tracking only, for safety only, and only during travel to and from the institution
  • By comparison, the healthcare carve-out in the same Schedule is scoped to protection of the child’s health and does not extend to secondary use

Where the exemption stops, which is the part to internalise

The Fourth Schedule exempts two provisions, for a defined set of purposes. That is the whole of what it does. Critically, the exemption is purpose-bound rather than institution-bound - it attaches to what you are doing, not to what you are. A school marking attendance is covered. The same school passing parent phone numbers to a coaching centre is not, because that is neither an academic activity nor student safety. This distinction is where almost every school’s genuine exposure sits, and it is the part schools have historically been most casual about.

What the school is doingCovered by the exemption?
Marking attendance, recording marks, writing conduct remarksYes - academic activity
Safety measures for an enrolled studentYes - student safety
Bus location tracking during the school commuteYes - safety, but only during travel
Sharing parent contact details with a coaching centreNo
Giving a class list to a uniform or book supplierNo
Using student photographs in admission marketingNo
Behavioural analytics sold or shared with a third partyNo
Keeping full records of students who left years ago, with no stated purposeNo - this is a retention problem, not a consent one

The six obligations that apply to every school regardless

The consent exemption does not touch the rest of the framework. Whatever else is true, a school still owes all of the following, and none of them are satisfied by a consent line on the admission form.

  • An itemised notice - a specific account of what is collected and why, not a clause saying data may be used for school purposes
  • Purpose-limited retention - defined retention periods tied to a purpose, and a reason you still hold what you hold
  • Reasonable security safeguards - a substantive obligation, not a best-effort aspiration
  • Breach notification within 72 hours
  • Data principal rights - parents and students can ask what you hold, ask for correction, and in defined circumstances ask for erasure
  • Purpose discipline on every use outside academics and safety, which is where third-party sharing lives

The 72-hour clock assumes you would notice

This is the obligation that catches organisations out, because the deadline is the easy half. Seventy-two hours presumes detection. If a fee spreadsheet left on a former accountant’s laptop last March, what is the mechanism by which anyone at your school finds out, let alone within three days? For most schools the honest answer is that there is no mechanism at all. That is not a consent problem and no form fixes it - it needs access control, an audit trail, and data living somewhere you can actually see it.

There is a regulator now

The Rules establish the Data Protection Board with a chairperson and four members, headquartered in Delhi. There is now a body whose function is to receive complaints. Separately, entities designated as Significant Data Fiduciaries take on heavier duties, including an India-based Data Protection Officer, independent audits and data protection impact assessments. Most single-campus schools will not fall into that category. Large multi-branch groups should establish whether they do rather than assume they do not.

A nine-month plan that does not start with consent forms

None of the following needs a lawyer to begin and none of it needs software. Do them in this order, because each one depends on the one before it.

  • Write down every place student data actually lives. Not the official answer - the real one: the management system, the fee spreadsheet, staff WhatsApp groups, the transport contractor’s list, the photographer’s shared drive, the front-office notebook, the laptop of the teacher who left in June. This takes a morning, it is always worse than expected, and everything else depends on it.
  • For each entry, name the purpose. If you cannot state why you hold something, you have your answer about whether to keep holding it.
  • Fix third-party sharing next, because it is your largest real exposure and the exact thing the exemption does not cover. Every vendor with access needs a reason and a written arrangement.
  • Set retention periods and then actually delete on schedule. Deleting is the step everybody skips.
  • Rewrite the admission-form consent into a genuine itemised notice.
  • Close the informal channels. Student data in personal WhatsApp groups, personal spreadsheets and personal laptops is where breaches come from, and it is the hardest thing to change because it is the most convenient thing your staff do.
  • Name one person who owns this. A person, not "the office".

What software does, and what no software can do

We build school management software, so weigh this section accordingly. Software genuinely helps with part of this, and cannot touch the rest.

What it genuinely helps with

Role-based access, so a class teacher cannot pull the whole school’s fee ledger. Encryption and proper hosting, so student data is not sitting on an office desktop. An audit trail, which is what makes a breach detectable inside 72 hours rather than never. One searchable record, so you can answer a parent’s access request without a filing-cabinet expedition. And consolidation - moving data out of personal spreadsheets and chat groups into one controlled system shrinks the informal-channel problem, which is the real risk in most schools.

What it cannot do

Make you compliant. The data inventory is yours. The purpose decisions are yours. The retention policy is a judgement about your school, not a settings toggle. The vendor relationships are yours to renegotiate. Any vendor claiming their product delivers DPDP compliance is selling something that does not exist, and between now and May 2027 you should expect to hear that claim often. Treat it as information about the vendor.

Not legal advice, and why that matters here

This is a summary of a framework that is still settling, written by a software vendor with a commercial interest in the sector. The Fourth Schedule position in particular turns on how strictly limited to the stated purposes is read in practice, and that reading is not yet settled by any regulator or court. Treat this as a starting point for a conversation with your own adviser, verify against the Rules themselves, and take advice specific to your institution before making compliance decisions. Sources used: the DPDP Rules 2025 as published by MeitY, the MeitY and DSCI FAQs on children’s and persons-with-disability personal data, and the published DPDP Rules summaries from EY and PwC.

Frequently asked questions

Does the DPDP Act apply to schools in India?

Yes, schools are data fiduciaries and the framework applies to them. But the Fourth Schedule of the DPDP Rules 2025 switches off the verifiable parental consent requirement (Section 9(1)) and the tracking restrictions (Section 9(3)) for schools, where processing is strictly limited to academic activities or the safety of enrolled students. Every other obligation - notice, retention limits, security, 72-hour breach notification and data rights - applies to schools in full.

Do schools need verifiable parental consent to take attendance or record marks?

No. Attendance, marks, conduct remarks and student safety measures fall within the academic activities and student safety purposes named in the Fourth Schedule, which is exempt from the verifiable parental consent requirement. The Schedule expressly includes tracking and behavioural monitoring for academic activities.

What is the DPDP compliance deadline for schools?

12 May 2027. The DPDP Rules 2025 were notified on 13 November 2025, and Rules 3 and 5 to 16, plus 22 and 23, come into force eighteen months after publication. That is the date to plan against.

Does the school exemption cover sharing student data with vendors or coaching centres?

No. The exemption is purpose-bound, not institution-wide - it attaches to what you are doing rather than to what you are. Passing parent contact details to a coaching centre, giving a class list to a uniform supplier, or sharing behavioural data with a third party is neither an academic activity nor student safety, so none of it is covered. Third-party sharing is where most schools’ real exposure sits.

Can a school use student photographs in admission marketing?

Marketing is not an academic activity and it is not student safety, so it falls outside the Fourth Schedule exemption entirely. Schools using student photographs promotionally should treat that as a separate processing purpose requiring its own basis, and should not assume the academic exemption reaches it.

What must a school do within 72 hours of a data breach?

Breach notification is required within 72 hours. The harder half of that obligation is detection: the deadline assumes someone at the school would notice. Most schools have no mechanism to detect that student or fee data has leaked from a spreadsheet or a personal laptop, which is an access-control and audit-trail problem rather than a consent problem.

Is our school a Significant Data Fiduciary?

Most single-campus schools will not be designated as Significant Data Fiduciaries. Those that are take on additional duties, including appointing an India-based Data Protection Officer, commissioning independent audits and carrying out data protection impact assessments. Large multi-branch school groups should establish their position rather than assume they are outside the category.

Does school management software make a school DPDP compliant?

No, and no vendor can honestly claim otherwise. Software helps materially with access control, encryption, audit trails and answering data access requests, and consolidating data into one controlled system reduces the informal-channel risk. But the data inventory, the purpose decisions, the retention policy and the third-party vendor relationships are the school’s responsibility and cannot be delegated to a product.

Related guides & pages